Home Blog Page 378

UK Fortunate to Avoid a C1 Cyber Attack: NCSC Chief

In an interview with The Guardian, UK’s National Cyber Security Centre Chief, Ciaran Martin agreed that the country has been fortunate, not to have encountered a category one (C1) cyber-attack, yet. However, he also mentioned that it was a matter of “when, not if”, conjecturing it might happen within two years. The NCSC is going to publish a report on the success and failures of its strategies since its inception in 2016.

Interestingly Martin had made a similar comment last year, during an interview with Wired. “In the first few months since the National Cyber Security Centre formally came into being, we’ve dealt with around 60 to 70 Category Two and Three attacks per month. We’ve never had a Category One attack – a serious national emergency – that we’ve seen in other countries. Those that require co-ordination from the national authority on cyber security are in the region of 60 to 70 per month,” said Martin.

The most powerful cyber-breach in the form of WannaCry hit UK last year, a C2 attack that paralyzed operations in hospitals. 34 C2 and 762 C3 attacks were recorded last year by NCSC. US, France, and most European countries have already been victims of cyber-attacks, raising the probability bar for UK to be the next victim of a C1 breach.

Amid Cyber Security Concerns AEC Counted Ballots by Hand

The National Audit Office of Australia recently pointed out to the Australian Electoral Commission (AEC), that they didn’t conform to the basic cyber security requirements, during the 2016 federal elections. While spending $27.2 million for acquiring automatic ballot scanning technology, the AEC didn’t pay much heed to the compliance part. Adding to the woes, they decided to count the ballots by hand after Signals Directorate raised security concerns, thereby adding more than $6 million to the expenses.

The AEC is said to have taken the risk due to time constraints.  Auditor-General Grant Hehir commented, “Insufficient attention was paid to ensuring the AEC could identify whether the system had been compromised. The level of IT security risk accepted by the AEC on behalf of the Australian Government and the extent of the non-compliance with the Australian Government IT security framework, was not transparent. The wording used in some of the internal records and published materials would generate confidence in the security of the system whereas the underlying assessments indicated significant risk.”

However, Electoral Commissioner, Tom Rodgers maintained his confidence in the integrity of the data, saying, “A review by the Australian Signals Directorate and the implementation of eight mitigation measures to address their 19 recommendations, provided me with added assurance that the risk of the data being tampered with was understood.”

This comes after the recent concern shown by Australia’s Cyber Security Research Centre (CSRC) in the country’s weak cyber security standards.

Federal Agencies fail to install anti-spoofing email tools: IAITAM

With an estimated one out of eight emails that appear to come from federal government accounts actually being fraudulent, it is “totally unacceptable and a complete dereliction of duty to taxpayers” that almost half (45 percent) of federal agency email domains have failed to meet a deadline to install anti-spoofing software, according to Dr. Barbara Rembiesa, president and CEO of the International Association of IT Asset Managers (IAITAM).

IAITAM has long been critical of the failure of federal agencies to maintain proper Information Technology Asset Management (ITAM) procedures, including the proper accounting for all hardware and rigorous maintenance of software, with timely installation of patches and upgrades.

A new review by found that 45 percent of federal agencies missed a Homeland Security Department deadline to install a new anti-spoofing email security tool.  Ironically, the Homeland Security Department was among the worst offenders with 85 percent of its own email domains not protected.  The new tool is designed to eliminate or substantially reduced phony (or “spoofed”) email that appears to be coming from U.S. government agencies.

According to NextGov: “DMARC, which stands for Domain-based Message Authentication, Reporting and Conformance, essentially pings a sender’s email domain—irs.gov, for example—and asks if the sender — say, Martha Stewart— is legitimate. If the domain says the sender is illegitimate, DMARC can send the email to the recipient’s spam folder or decline to deliver it entirely.”

IAITAM President and CEO Barbara Rembiesa said: “What is it going to take for the federal government to start taking its email situation seriously?  You would think that the Clinton email scandal would have caused people to sit up and start flying right when it comes to managing federal email systems, but here we see new evidence of something that is totally unacceptable and a complete dereliction of duty to taxpayers.”

Rembiesa added: “Where is the focus on Information Technology Asset Management in federal agencies?  Heads would roll at private sector companies that allowed a deadline like this to be missed at half of all domains targeted for a major software upgrade or addition like this.  It is astonishing to me that a need could be identified, a solution chosen, and a deadline set, and then have this much failure result.  The federal government is never going to clean up its IT-related waste and inefficiency until it streamlines federal technology purchasing and oversight and imposes consistent rules with real consequences for non-compliance.”

Rembiesa concluded: “There is no question here about what needs to be done; the only mystery is why the federal government can’t get its act together and start looking out for the interests — and dollars — of taxpayers.”

A Single Commonwealth-led Agency will Pull Australia from Its Uncoordinated CyberSecurity Situation

In an interesting revelation, David Irvine, chairman of Australia’s Cyber Security Research Centre (CSRC), revealed that the country’s competence to thwart cyber-breaches is ‘relatively weak and uncoordinated’. His comments were part of a submission to a parliamentary enquiry, on the ‘impact of new and emerging information and communications technology’.

“Australia’s national capacity to counter threats and criminal activity using cyber investigative tools is relatively weak, uncoordinated, and dispersed across a range of agencies in both Commonwealth and state jurisdictions. Countering cybercrime in Australia will be most effective when investigative support mechanisms are concentrated and coordinated on a national basis, utilizing skills and technical capabilities developed in the national security area to strengthen law enforcement activity, and vice versa,” commented Irvine.

According to a report published in Australian Broadcasting Corporation, David, who was the ex-boss of Australian Security Intelligence Organization popularly known as ASIO, remarked that a single commonwealth-led cooperative agency is the call of the hour. “Such an agency might fall within the ambit of the Department of Home Affairs, either as a separate entity or associated with the Australian Cyber Security Centre or the Australian Federal Police and Australian Criminal Intelligence Commission, and with a close working relationship with the skills-intensive Australian Signals Directorate,” he remarked.

This Text Message will ‘Blow up’ your Apple Gadgets

Reliance Jio’s Coronavirus Symptom Checker App Exposes User Data

Another in the series of text related cyber-breaches has hit Apple. The ChaiOS bug hasn’t found any solution yet. Being shared in the form of a link this freezes the receiver’s phone and causes a frenzy in your messages app, distressing your iPhone, iPad and Mac. Clicking on the URL sent through messages creates a long tag, often crashing the OS. The automatic preview feature of the messages app unleashes the havoc. Deleting the messages as soon as they hit your inbox is the only fix available yet.

A similar nasty video link had led to wreckage in Safari and iOS devices in 2016. With no fixes available yet, Apple device users are at an alert and cautious of the messages hitting their smartphones. An update from Apple is being expected to dispose-off the bug.  Till then your devices are vulnerable.

Industry expert Graham Cluley said in an interview with The Independent said, “Something about the so-called ChaiOS bug’s code gives your Apple device a brainstorm. Ashamed about the mess it gets itself in, Messages decides the least embarrassing thing to do is to crash. Nasty. But, thankfully, more of a nuisance than something that will lead to data being stolen from your computer or a malicious hacker being able to access your files.”

Jarvis to protect driverless cars

Jarvis to protect driverless cars

Phone maker, Blackberry Ltd. has developed a cybersecurity software, Jarvis, for self-driving cars. Sharing the same name as the A.I. developed by Marvel’s Tony Stark, also the Iron Man, Blackberry’s Jarvis is also an advanced security software for the much-arguable self-driven cars.

Launching the product at the North American International Automotive Show (NAIAS), John Chen, Executive Chairman and CEO of Blackberry said, “Connected and autonomous vehicles require some of the most complex software ever developed, creating a significant challenge for automakers who must ensure the code complies with industry and manufacturer-specific standards while simultaneously battle-hardening a very large and tempting attack surface for cybercriminals.”

Pointing out the biggest challenge for Original Equipment Manufacturers (OEMs), of outsourcing their software requirements to different service-providers, Chen mentioned, “Jarvis is a game-changer for OEMs because for the first time they have a complete, consistent, and near real-time view into the security posture of a vehicle’s entire code base along with the insights and deep learning needed to predict and fix vulnerabilities, ensure compliance, and remain a step ahead of bad actors.”

Being offered as a pay-as-you-go service, Jarvis will allow easier evaluation of software in production with complete adherence to industry guidelines. While Jarvis is already being marketed to leading automakers, Blackberry is establishing its brand presence in the industry with recent vehicle partnership with software giants like Qualcomm, Baidu, China’s Internet giant, Delphi and more.

McAfee recognized as a leader in Gartner Magic Quadrant

BUSINESS WIRE

McAfee, cybersecurity firm,   today announced that Gartner, Inc. has named the company a Leader in the “Gartner Magic Quadrant for Intrusion Detection and Prevention Systems” (IDPS) for the 11th time.1 The McAfee® Network Security Platform (NSP) is a complete network threat and intrusion prevention solution that protects systems and data wherever they reside across datacenter, cloud, and hybrid enterprise environments. Utilizing multiple signature-less detection technologies, McAfee NSP finds and blocks advanced targeted attacks on the network with unmatched speed, accuracy, and simplicity.

“We are proud to be one of three companies recognized by Gartner as a Leader in the 2018 Magic Quadrant for Intrusion Detection and Prevention Systems and, to us, more largely, our exceptional performance in enabling effective cybersecurity operations,” said Raja Patel, vice president and general manager of corporate products at McAfee. “Our continued presence in this Gartner report and leadership in areas such as TI context and heuristic techniques that lessen reliance on signatures, are among the many reasons we feel we continue to lead in this category.”

McAfee NSP enables security to easily scale across multi and hybrid cloud environments based upon the changing dynamics of virtualized workloads. With support for network virtualization, administrators can quickly deliver network protection to new, existing and moving workloads, while simplified licensing enables inspection throughput to easily scale across any combination of public and private clouds. McAfee NSP provides enterprise organizations with unparalleled advanced threat prevention, including:

Signature-less defenses – multiple advanced engines that do not require signatures, to protect against advanced and unknown threats

Cloud scalability – administrators can easily scale security to meet the needs of current and future cloud deployments

Performance – deep inspection of network traffic while maintaining line-rate speeds

Streamlined security management – the McAfee Unified Defense Architecture integrates real-time McAfee Global Threat Intelligence Exchange feeds with McAfee Advanced Threat Defense and McAfee Cloud Threat Detection solutions

Actionable workflows – out-of-the-box correlation workflows that organize multiple alerts into single events (like a mini SIEM)

Visibility and control – the first and only IPS solution to combine advanced threat prevention and application awareness into a single security decision engine, plugging infrastructure gaps

Kotlin-developed Malware Doing Rounds in Google Play Store

A malware developed using the Kotlin programming language is the new cause of concern for Google Play Store. It was recently found that Kotlin can be used to develop nasty apps, which will be difficult to detect. Trend Micro, a cyber-defense and security firm, discovered a malicious app posing as Swift Cleaner for optimizing Android devices. The Kotlin-developed app is capable of information theft and click ad fraud among other damages.

Kotlin was hailed by Google as a healthy language with in-built safety features for apps. The programming language was written by JetBrains, a Russian Java developer company. Google adopted Kotlin approved Android development in 2017. This information can be a worrying situation for other leading users of the programming language which include Netflix, Twitter and Pinterest. The application is allegedly capable of carrying out remote command execution and sign up users without permission for premium SMS services. While Google was informed of this security threat by Trend Micro, Google confirmed that Google Play Protect is capable of handling user safety from such cyber-breaches. The application already displays more than 1000 downloads in the app store, an indication of the rise in threat.

LALA World Collaborates with VIBE Cybersecurity on a Joint Development Project

CISA Unveils Joint Cyber Defense Collaborative to Boost Cybersecurity

Singapore based LALA World collaborated with cryptographic technology leader, VIBE Cybersecurity International LLC to create a fully secured financial-exchange platform. LALA World, which primarily focuses on migrants and unbanked population, caters to individuals, small businesses and micro-entrepreneurs. In wake of the recent cyber-breach events in the financial world, the urgency to adopt robust information security measures is being felt across the industry.

Sankalp Shangari, founder and CEO of the Fintech firm said, “Our vision to provide financial freedom and accessibility for the world’s over 2 billion unbanked and underserved has, at its foundation, our commitment to technological excellence and forward-looking cryptography that eliminates the threat of security breaches. Thanks to our partnership with VIBE, our current and prospective ICO investors can embrace our technology and its promise, armed with the knowledge that we are leading with security – not trying to apply it after the fact.”

VIBE or Verifiable Identity-Based-Encryption has patented its technology that eliminates the need for PKI or Private Key Infrastructure, through integration of biometrics in distributed blockchain ledger technology. The certificate-less initiative is aimed towards eliminating cyber-attacks through intermediaries, in the words of Shangari.

VIBE’s CEO, Bill Montgomery added, “The entire VIBE team is delighted by the opportunity to render secure the LALA World digital platform and wallet which is so critical to this exciting company’s mission to provide financial services to the world’s unbanked. Given the nature of our business, we are acutely aware of the tens of millions of dollars that have been stolen from ICO-funded companies, worldwide. I applaud LALA World for taking the steps necessary to eliminate any such possibility. It speaks to its leader’s superior customer focus.” The commencement of the alliance has begun with VIBE-certified technology partner, QuantumCiel, taking the leads.

Intel Creates New Internal Cybersecurity Group

intel

The recent encounters with Spectre and Meltdown techniques, owing to faults in its microprocessors has shaken the world’s largest chipmaker, Intel. With little options but to introduce safety measures to preserve its brand reputation, a new internal security group was enacted on Monday, January 8, 2018, as the ‘Intel Product Assurance and Security’.

Although there has been no confirmation by Intel on this report, it is heard on the grapevine that Leslie Culbertson, Human Resources chief at Intel, will be presiding over this newly formed group. There is also news of relocation of other leading executives into this cybersecurity group, including Intel Vice President Steve Smith.

According to a report by Oregonian, ahead of his keynote address on Monday, at the Consumer Electronics Show in LA, Brian Krzanich, CEO of Intel sent out a memo to its employees stressing the need to maintain the customer-first attitude while responding diligently to customer requests. “It is critical that we continue to work with the industry, to excel at customer satisfaction, to act with uncompromising integrity, and to achieve the highest standards of excellences.” He said.

Krzanich revealed “Tangle Lake” a 49-qubit superconducting quantum chip at the Consumer Electronics Show. As the chipmaker is setting new benchmarks, it is quite likely that they need to adopt and display effective measures, for the recently discovered imperfections in its products.